boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-754

Weakness type CWE-754 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
67560

Monthly trend

▁▁▁▂▁▂▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▇▃▇█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 16 · 2026-06 5 · 2026-07 16 · 2026-08 18

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-256397.583.4Axios affected by Denial of Service via __proto__ Key in mergeConfig
CVE-2026-59467.577.7Invalid handling of CLASS != IN
CVE-2026-399298.770.4Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP
CVE-2024-422847.857.6tipc: Return non-zero value from tipc_udp_addr2str() on error
CVE-2025-385667.545.5sunrpc: fix handling of server side tls alerts
CVE-2024-502845.543.0ksmbd: Fix the missing xa_store error check
CVE-2025-133929.842.7
CVE-2026-568126.341.2Phoenix JavaScript presence client crashes on presence keys colliding with Object.proto…
CVE-2026-80919.838.8Incorrect boundary conditions in the Audio/Video: Playback component
CVE-2026-443246.535.2free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interf…
CVE-2026-443167.533.8free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 40…
CVE-2026-542695.333.6protobufjs: Schema-derived names can shadow runtime-significant properties
CVE-2026-443227.532.3free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failur…
CVE-2026-06679.330.1
CVE-2026-443176.528.2free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with miss…
CVE-2026-465417.527.8Nimiq network-libp2p: DHT query poisoning via first-record verification failure
CVE-2026-691857.527.7Socket.IO: Zero-attachment Memory Exhaustion
CVE-2026-456787.527.3OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
CVE-2026-472168.726.6Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint
CVE-2026-547756.526.6CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux11
juniper networks5
free5gc4
indian motorcycle4
atn-b12
eugeny2
mattermost2
nimiq2
palo alto networks2
@fastify/busboy1
axios1
corewcf1
cure531
drupal1
epsilla-cloud1